Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesAIX 610000 : U807555- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U807555 which is relatedto the security of the package bos.adt.baseYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32508 AIX 610000 : U802797- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U802797 which is relatedto the security of the package perl.rteYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32507 dotCMS search_query Parameter Cross-Site Scripting Vulnerability- (Found June 29, 2008 ) High Risk -- The remote host is using dotCMS, an open-source J2EE Java webcontent management system. The version of dotCMS installed on the remote host fails to sanitizeinput to the 'search_query' parameter of the 'search-results.dot'script before using it to generate dynamic HTML output. An attackermay be able to leverage this issue to inject arbitrary HTML and scriptcode into a user's browser to be executed within the security contextof the affected site.http://www.edgeos.com/threats/32506 AEC Subscription Manager Component usage Parameter SQL Injection Vulnerability- (Found June 29, 2008 ) Critical Risk -- The version of the AEC Subscription Manager component for Joomla andMambo installed on the remote host fails to sanitize user-suppliedinput to the 'usage' parameter before using it in database queries in'acctexp.class.php'. Regardless of PHP's 'magic_quotes_gpc' setting,an attacker may be able to exploit this issue to manipulate databasequeries, leading to disclosure of sensitive information, modificationof data, or attacks against the underlying database.http://www.edgeos.com/threats/32505 Adobe AIR Detection- (Found June 29, 2008 ) Low Risk -- Adobe AIR is installed on the remote host. It is a browser-independent runtime environment that supports HTML, JavaScript, andFlash code and provides for Rich Internet Applications (RIAs).http://www.edgeos.com/threats/32504 VMware Products Multiple Vulnerabilities (VMSA-2008-0008)- (Found June 29, 2008 ) High Risk -- A VMware product installed on the remote host is affected by multiple vulnerabilities. - A heap overflow vulnerability in VMware Host Guest File System (HGFS), could allow a guest to execute arbitrary code subject to the privileges of the user running 'vmx' process. In order to successfully exploit this issue a folder should be shared on the host system and sharing should be enabled, which is disabled by default. - A vulnerability in Virtual Machine Communication...http://www.edgeos.com/threats/32503 SuSE Security Update: Security update for XEmacs (xemacs-packages-5250)- (Found June 29, 2008 ) Critical Risk -- Xemacs automatically loaded fast-lock files which allowedlocal attackers to execute arbitrary code as the userediting the associated files (CVE-2008-2142).http://www.edgeos.com/threats/32502 Solaris 10 (i386) : 137020-02- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 137020-02(SunOS 5.10_x86: snmpXdmid patch).Date this patch was last updated by Sun : Wed Jun 11 10:50:50 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/32501 Solaris 10 (i386) : 137018-02- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 137018-02(SunOS 5.10_x86: crontab patch).Date this patch was last updated by Sun : Fri May 30 08:35:05 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/32500 Solaris 10 (i386) : 136840-01- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 136840-01(Service Tags SunOS 5.10_x86).Date this patch was last updated by Sun : Tue May 20 08:23:16 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/32499 |